Privacy Policy
Last updated:
This policy explains what personal data ZapTranslator processes, why, and what rights you have over it. It covers zaptranslator.com and the platform.
It is written in plain language and describes the system as it actually works. Where a kind of processing does not exist yet because the feature has not shipped, we say so.
1. Who is responsible
ZapTranslator is operated by Ricardo Biruel (Infodesk Technologies). For anything to do with privacy, including exercising your rights: support@zaptranslator.com.
2. Two different roles — and the difference matters
We are the controller of your account data: email address, authentication, plan, usage and billing. We decide why and how that data is processed.
We are a processor of the content that flows through the platform — the conversations between you and your own customers. There, you decide: we only carry out your instructions.
This is not legal decoration. It means that if one of your customers asks for their messages to be deleted, you are the one who answers that request, and we give you the tools to honour it.
3. What data we process
Today, with the features that exist:
- Account identity: your email address and, if you provide it, your name. Your password never reaches us — our identity provider stores it, hashed.
- If you sign in with Google: the name, profile picture and email address Google sends us after you authorise it. We do not request or receive access to Gmail, Drive, Calendar or any other service.
- Technical operating data: IP address, access timestamps, browser type and error logs.
- Once you connect a WhatsApp number (feature in development): messages sent and received, phone numbers, display names, attached media and timestamps. That content is processed on your instruction.
4. What we use it for
- Authenticating you and keeping your session alive.
- Delivering the service you signed up for: connecting channels, translating, routing and storing conversations.
- Measuring usage for billing, where a paid plan applies.
- Keeping the platform secure and available: detecting abuse, investigating failures, preventing fraud.
- Sending account-essential messages — email confirmation, password reset and operational notices.
5. Legal basis
Under the GDPR — *General Data Protection Regulation* (EU Regulation 2016/679) — and Brazil's LGPD — *Lei Geral de Proteção de Dados* (Law 13.709/2018) — we rely on:
- Performance of a contract: everything required to deliver the service you signed up for.
- Legitimate interests: platform security, abuse prevention and service improvement, always weighed against your rights.
- Legal obligation: retaining tax and accounting records where required.
- Consent: only where it is asked for clearly and separately. You may withdraw it at any time, without affecting processing already carried out.
6. Who we share it with
We do not sell personal data and we do not share it for advertising. We share only with the vendors the service needs to run, each limited to its function:
- WorkOS (United States) — authentication and identity management.
- Neon (Germany, eu-central-1) — database.
- Fly.io (France, cdg) — application servers.
- Vercel (United States, with distributed delivery) — hosting for the web interface.
- Resend (Ireland, eu-west-1) — transactional email delivery.
- Meta Platforms — when you use the official WhatsApp Business API, messages travel through their infrastructure under their terms.
- AI translation providers — the text to be translated is sent to the provider. We only contract providers that do not use that content to train their own models.
7. Where the data lives
Business data stays in the European Union: database in Frankfurt (Germany), application servers in Paris (France), and email delivery in Ireland.
Authentication is operated by WorkOS, based in the United States. That international transfer is covered by the European Commission's Standard Contractual Clauses. Only your email address and session data travel for that purpose — never conversation content.
8. How long we keep it
- Account data: for as long as the account exists, and up to 30 days after closure, to allow you to change your mind.
- Conversations and media: for the period you set in your workspace settings. With no setting, for as long as the account exists.
- Technical and security logs: up to 12 months.
- Tax documents: for the period the law requires — typically 5 years in Brazil, 6 in Spain and 10 in Portugal.
9. Your rights
At any time you may: confirm whether we process your data, access it, correct it, request erasure, request portability in a machine-readable format, object to processing based on legitimate interests, request restriction of processing, and withdraw consent.
Write to support@zaptranslator.com. We answer within 30 days, at no cost.
If you believe we are handling your data improperly, you may complain to the supervisory authority in your country — the CNPD in Portugal, the AEPD in Spain, the ANPD in Brazil, or the authority of the Member State where you live.
10. Security
All traffic is encrypted in transit (TLS). We never store passwords ourselves. Access to a workspace's data is restricted to its members.
Our operations team does not access customer conversation content. Support that requires such access happens only with your explicit authorisation, time-limited and recorded in an audit trail.
No system is immune. If an incident occurs that could put your rights at risk, we will notify you and the competent authority within the statutory deadlines.
11. Minors
ZapTranslator is a business tool and is not directed at anyone under 18. We do not knowingly collect data from minors. If we learn of such an account, it will be removed.
12. Changes
When this policy changes materially, we notify you by email and update the date at the top. Changes that broaden how we process your data take effect only after that notice.